Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hamza Khaled

#50544of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2026-69057
5.3
2026-08-07
Sonatype · Nexus Repository 3 · CVE-2026-17595
**Name of the Vulnerable Software and Affected Versions** Nexus Repository 3 (affected versions not specified) **Description** Insufficient sandboxing of JEXL (Java Expression Language) expressions used in Content Selectors allows an account with the `nexus:selectors:create` permission to construct expressions that read Java object properties not intended for exposure. This leads to the disclosure of internal JVM (Java Virtual Machine) class metadata, including class and classloader names. This issue does not allow for method invocation, object construction, or arbitrary code execution. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.